Git commit, but play nice with conventions.
72%
Total Score
83
50
94
50
100
Fourteen runtime dependencies create a meaningful maintenance surface for a command-line tool, but the package has a long release history and an established repository.
The package runs a prepare lifecycle script during installation, which adds install-time behavior and modest dependency risk even though no maliciousness conclusion follows from it.
No commits or active maintainers were recorded in the last three months, a meaningful maintenance warning despite the recent package release and repository push.
The repository uses established build tooling, but no security scanning tools were detected, leaving a security-process gap.
The repository has no published security policy, reducing transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
glob Version 7.2.3 | — | — |
dedent Version 0.7.0 | — | — |
lodash Version 4.18.1 | — | — |
is-utf8 Version ^0.2.1 | — | — |
cachedir Version 2.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.